Earlier quoted context omitted.
Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?
This article is more or less total bullshit. At _best_ that device might be a mechanism to cause failure intentionally. And there are tons of ways to detect it with commodity technology, and plenty of vendors who implement that technology for assembly manufactures commercially.
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
191–200 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#192Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#193Earlier quoted context omitted.
First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?
> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?
It's the unknown unknowns that get you.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#194Earlier quoted context omitted.
SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…
But without the IPMI kernel modules loaded, IPMI is harmless, right ?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#195Earlier quoted context omitted.
they have literally every reason to deny and literally no reason to say it's true
Except, you know, to avoid committing securities fraud by making a material misrepresentation.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#196Earlier quoted context omitted.
> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…
You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…
To give a bit of background, when you type your PIN on credit card terminal it is not the terminal application that is really getting the pin (well, except for special credit cards but that is really problem of the Bank that issued the card). The Visa/Mastercard mandate that the application don't have control over the PIN and that the PIN entry uses physically separate keyboard and display.
To achieve this, the keyboard and the display is galvanically separated for the duration of the PIN entry and the PIN is transferred directly to the HSM where it is being encrypted before it is transferred to the application processor for the rest of processing.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#197I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Why don't you guys consider to expose this by suing the bad manufacturer? I believe this could help other truely honest manufacturers both in and outside China to beat the wrong doers.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#198Earlier quoted context omitted.
> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…
The chinese government is probably not interested enough in credit card numbers to warrant involvement.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#199Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#200Earlier quoted context omitted.
You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…
The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…
https://www.commbank.com.au/business/merchant-services/eftpo...